IOS 10.2.1 正式版推出 - iOS

By Jack
at 2017-01-24T05:30
at 2017-01-24T05:30
Table of Contents
https://support.apple.com/en-us/HT207482
This document describes the security content of iOS 10.2.1.
iOS 10.2.1
Released January 23, 2017
Auto Unlock 自動解鎖問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:當Apple watch離開你的手時仍然會自動解鎖
Impact: Auto Unlock may unlock when Apple Watch is off the user's wrist
Description: A logic issue was addressed through improved state management.
CVE-2017-2352: Ashley Fernandez of raptAware Pty Ltd
Contacts 聯絡人問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意的聯絡人資料卡可能造成程式中止
Impact: Processing a maliciously crafted contact card may lead to unexpected
application termination
Description: An input validation issue existed in the parsing of contact
cards. This issue was addressed through improved input validation.
CVE-2017-2368: Vincent Desmurs (vincedes3)
Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges
Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2017-2370: Ian Beer of Google Project Zero
Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges
Description: A use after free issue was addressed through improved memory
management.
CVE-2017-2360: Ian Beer of Google Project Zero
libarchive 資料庫封存問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:打開惡意產生的封包可能導致程式碼任意執行
Impact: Unpacking a maliciously crafted archive may lead to arbitrary code
execution
Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2016-8687: Agostino Sarubbo of Gentoo
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A prototype access issue was addressed through improved
exception handling.
CVE-2017-2350: Gareth Heyes of Portswigger Web Security
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed through
improved memory handling.
CVE-2017-2354: Neymar of Tencent's Xuanwu Lab (tencent.com) working with
Trend Micro's Zero Day Initiative
CVE-2017-2362: Ivan Fratric of Google Project Zero
CVE-2017-2373: Ivan Fratric of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: A memory initialization issue was addressed through improved
memory handling.
CVE-2017-2355: Team Pangu and lokihardt at PwnFest 2016
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed through
improved input validation.
CVE-2017-2356: Team Pangu and lokihardt at PwnFest 2016
CVE-2017-2369: Ivan Fratric of Google Project Zero
CVE-2017-2366: Kai Kang of Tencent's Xuanwu Lab (tencent.com)
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A validation issue existed in the handling of page loading. This
issue was addressed through improved logic.
CVE-2017-2363: lokihardt of Google Project Zero
CVE-2017-2364: lokihardt of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意網站可以打開彈出式視窗
Impact: A malicious website can open popups
Description: An issue existed in the handling of blocking popups. This was
addressed through improved input validation.
CVE-2017-2371: lokihardt of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A validation issue existed in the handling of variable handling.
This issue was addressed through improved validation.
CVE-2017-2365: lokihardt of Google Project Zero
WiFi 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:有啟動鎖定的裝置可以在操作下短暫的顯示首頁
Impact: An activation-locked device can be manipulated to briefly present the
home screen
Description: An issue existed with handling user input that caused a device
to present the home screen even when activation locked. This was addressed
through improved input validation.
CVE-2017-2351: Sriram (@Sri_Hxor) of Primefort Pvt. Ltd., Hemanth Joseph
--
This document describes the security content of iOS 10.2.1.
iOS 10.2.1
Released January 23, 2017
Auto Unlock 自動解鎖問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:當Apple watch離開你的手時仍然會自動解鎖
Impact: Auto Unlock may unlock when Apple Watch is off the user's wrist
Description: A logic issue was addressed through improved state management.
CVE-2017-2352: Ashley Fernandez of raptAware Pty Ltd
Contacts 聯絡人問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意的聯絡人資料卡可能造成程式中止
Impact: Processing a maliciously crafted contact card may lead to unexpected
application termination
Description: An input validation issue existed in the parsing of contact
cards. This issue was addressed through improved input validation.
CVE-2017-2368: Vincent Desmurs (vincedes3)
Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges
Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2017-2370: Ian Beer of Google Project Zero
Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges
Description: A use after free issue was addressed through improved memory
management.
CVE-2017-2360: Ian Beer of Google Project Zero
libarchive 資料庫封存問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:打開惡意產生的封包可能導致程式碼任意執行
Impact: Unpacking a maliciously crafted archive may lead to arbitrary code
execution
Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2016-8687: Agostino Sarubbo of Gentoo
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A prototype access issue was addressed through improved
exception handling.
CVE-2017-2350: Gareth Heyes of Portswigger Web Security
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed through
improved memory handling.
CVE-2017-2354: Neymar of Tencent's Xuanwu Lab (tencent.com) working with
Trend Micro's Zero Day Initiative
CVE-2017-2362: Ivan Fratric of Google Project Zero
CVE-2017-2373: Ivan Fratric of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: A memory initialization issue was addressed through improved
memory handling.
CVE-2017-2355: Team Pangu and lokihardt at PwnFest 2016
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed through
improved input validation.
CVE-2017-2356: Team Pangu and lokihardt at PwnFest 2016
CVE-2017-2369: Ivan Fratric of Google Project Zero
CVE-2017-2366: Kai Kang of Tencent's Xuanwu Lab (tencent.com)
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A validation issue existed in the handling of page loading. This
issue was addressed through improved logic.
CVE-2017-2363: lokihardt of Google Project Zero
CVE-2017-2364: lokihardt of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意網站可以打開彈出式視窗
Impact: A malicious website can open popups
Description: An issue existed in the handling of blocking popups. This was
addressed through improved input validation.
CVE-2017-2371: lokihardt of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A validation issue existed in the handling of variable handling.
This issue was addressed through improved validation.
CVE-2017-2365: lokihardt of Google Project Zero
WiFi 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:有啟動鎖定的裝置可以在操作下短暫的顯示首頁
Impact: An activation-locked device can be manipulated to briefly present the
home screen
Description: An issue existed with handling user input that caused a device
to present the home screen even when activation locked. This was addressed
through improved input validation.
CVE-2017-2351: Sriram (@Sri_Hxor) of Primefort Pvt. Ltd., Hemanth Joseph
--
Tags:
iOS
All Comments

By Kelly
at 2017-01-28T01:26
at 2017-01-28T01:26

By Edith
at 2017-01-31T02:24
at 2017-01-31T02:24

By Steve
at 2017-02-03T11:02
at 2017-02-03T11:02

By Isabella
at 2017-02-06T11:05
at 2017-02-06T11:05

By Edith
at 2017-02-09T13:20
at 2017-02-09T13:20

By Adele
at 2017-02-13T15:05
at 2017-02-13T15:05

By Franklin
at 2017-02-18T10:29
at 2017-02-18T10:29

By Franklin
at 2017-02-19T12:46
at 2017-02-19T12:46

By Quanna
at 2017-02-22T11:16
at 2017-02-22T11:16

By Barb Cronin
at 2017-02-26T03:36
at 2017-02-26T03:36

By Frederic
at 2017-02-26T07:03
at 2017-02-26T07:03

By Tracy
at 2017-03-02T09:33
at 2017-03-02T09:33

By Iris
at 2017-03-02T18:28
at 2017-03-02T18:28

By Suhail Hany
at 2017-03-05T02:02
at 2017-03-05T02:02

By Oliver
at 2017-03-06T22:34
at 2017-03-06T22:34

By Oliver
at 2017-03-08T20:25
at 2017-03-08T20:25

By Kumar
at 2017-03-13T06:55
at 2017-03-13T06:55

By Linda
at 2017-03-16T13:15
at 2017-03-16T13:15

By Rosalind
at 2017-03-21T01:40
at 2017-03-21T01:40

By Andrew
at 2017-03-21T13:10
at 2017-03-21T13:10

By Elizabeth
at 2017-03-25T00:07
at 2017-03-25T00:07

By Elma
at 2017-03-27T05:31
at 2017-03-27T05:31

By Noah
at 2017-03-29T04:47
at 2017-03-29T04:47

By Skylar Davis
at 2017-04-01T13:20
at 2017-04-01T13:20

By Hedwig
at 2017-04-02T19:18
at 2017-04-02T19:18

By Daniel
at 2017-04-04T23:35
at 2017-04-04T23:35

By Anonymous
at 2017-04-06T16:28
at 2017-04-06T16:28

By Carol
at 2017-04-08T07:06
at 2017-04-08T07:06

By Andy
at 2017-04-09T17:34
at 2017-04-09T17:34

By Bennie
at 2017-04-11T19:37
at 2017-04-11T19:37

By Skylar DavisLinda
at 2017-04-15T11:06
at 2017-04-15T11:06

By Carol
at 2017-04-16T08:22
at 2017-04-16T08:22

By Blanche
at 2017-04-17T13:48
at 2017-04-17T13:48

By Isabella
at 2017-04-19T00:52
at 2017-04-19T00:52

By Madame
at 2017-04-22T06:40
at 2017-04-22T06:40

By Hardy
at 2017-04-27T04:41
at 2017-04-27T04:41

By Brianna
at 2017-04-29T10:02
at 2017-04-29T10:02

By Hedy
at 2017-04-30T19:13
at 2017-04-30T19:13

By Gilbert
at 2017-05-03T11:51
at 2017-05-03T11:51

By Agnes
at 2017-05-06T21:33
at 2017-05-06T21:33

By Elizabeth
at 2017-05-08T19:46
at 2017-05-08T19:46

By Caroline
at 2017-05-09T16:47
at 2017-05-09T16:47

By Todd Johnson
at 2017-05-11T08:10
at 2017-05-11T08:10

By Yedda
at 2017-05-13T17:35
at 2017-05-13T17:35

By Callum
at 2017-05-13T20:17
at 2017-05-13T20:17

By Yuri
at 2017-05-17T10:41
at 2017-05-17T10:41

By Tracy
at 2017-05-20T16:02
at 2017-05-20T16:02

By Daniel
at 2017-05-23T12:45
at 2017-05-23T12:45

By Bethany
at 2017-05-24T22:36
at 2017-05-24T22:36

By Zora
at 2017-05-26T10:48
at 2017-05-26T10:48

By Emily
at 2017-05-28T00:02
at 2017-05-28T00:02

By Una
at 2017-05-30T14:58
at 2017-05-30T14:58

By Agnes
at 2017-06-02T05:50
at 2017-06-02T05:50

By Hamiltion
at 2017-06-06T02:32
at 2017-06-06T02:32

By Kristin
at 2017-06-09T08:24
at 2017-06-09T08:24

By Dinah
at 2017-06-10T19:52
at 2017-06-10T19:52

By Steve
at 2017-06-12T15:33
at 2017-06-12T15:33

By John
at 2017-06-14T12:15
at 2017-06-14T12:15

By Rachel
at 2017-06-16T19:47
at 2017-06-16T19:47

By Kumar
at 2017-06-18T21:16
at 2017-06-18T21:16

By Jake
at 2017-06-18T22:52
at 2017-06-18T22:52

By Zanna
at 2017-06-23T10:59
at 2017-06-23T10:59

By Audriana
at 2017-06-25T01:53
at 2017-06-25T01:53

By Barb Cronin
at 2017-06-28T07:13
at 2017-06-28T07:13

By Steve
at 2017-07-01T10:15
at 2017-07-01T10:15

By James
at 2017-07-04T10:18
at 2017-07-04T10:18

By Olga
at 2017-07-06T14:37
at 2017-07-06T14:37

By Callum
at 2017-07-08T21:57
at 2017-07-08T21:57

By Doris
at 2017-07-08T22:57
at 2017-07-08T22:57

By Franklin
at 2017-07-10T01:47
at 2017-07-10T01:47

By Susan
at 2017-07-14T13:27
at 2017-07-14T13:27

By Thomas
at 2017-07-18T22:45
at 2017-07-18T22:45

By Sandy
at 2017-07-22T20:06
at 2017-07-22T20:06

By Barb Cronin
at 2017-07-27T11:37
at 2017-07-27T11:37

By Connor
at 2017-07-28T19:59
at 2017-07-28T19:59

By Lauren
at 2017-07-31T11:48
at 2017-07-31T11:48

By Hazel
at 2017-08-04T09:19
at 2017-08-04T09:19

By Candice
at 2017-08-05T02:43
at 2017-08-05T02:43

By Jake
at 2017-08-08T22:34
at 2017-08-08T22:34

By Xanthe
at 2017-08-13T01:19
at 2017-08-13T01:19

By Ursula
at 2017-08-14T15:36
at 2017-08-14T15:36

By Mary
at 2017-08-15T17:10
at 2017-08-15T17:10

By Madame
at 2017-08-19T15:34
at 2017-08-19T15:34

By Rachel
at 2017-08-21T22:57
at 2017-08-21T22:57

By Rosalind
at 2017-08-24T09:09
at 2017-08-24T09:09

By Rachel
at 2017-08-24T18:44
at 2017-08-24T18:44

By Elvira
at 2017-08-26T13:24
at 2017-08-26T13:24

By Lily
at 2017-08-27T11:55
at 2017-08-27T11:55

By Suhail Hany
at 2017-08-30T16:07
at 2017-08-30T16:07

By Ethan
at 2017-09-04T01:16
at 2017-09-04T01:16

By Lauren
at 2017-09-07T01:25
at 2017-09-07T01:25

By Lauren
at 2017-09-08T08:20
at 2017-09-08T08:20

By Elma
at 2017-09-10T13:18
at 2017-09-10T13:18

By Zanna
at 2017-09-11T09:37
at 2017-09-11T09:37

By John
at 2017-09-14T06:29
at 2017-09-14T06:29

By Oscar
at 2017-09-14T20:43
at 2017-09-14T20:43

By Irma
at 2017-09-18T23:35
at 2017-09-18T23:35

By Madame
at 2017-09-23T09:52
at 2017-09-23T09:52

By Blanche
at 2017-09-27T06:16
at 2017-09-27T06:16

By Carol
at 2017-09-28T23:10
at 2017-09-28T23:10

By Kyle
at 2017-09-30T17:40
at 2017-09-30T17:40

By Adele
at 2017-10-01T10:22
at 2017-10-01T10:22

By Anonymous
at 2017-10-03T11:06
at 2017-10-03T11:06

By Erin
at 2017-10-07T18:57
at 2017-10-07T18:57

By Erin
at 2017-10-08T21:12
at 2017-10-08T21:12

By Odelette
at 2017-10-09T22:10
at 2017-10-09T22:10

By Odelette
at 2017-10-10T12:28
at 2017-10-10T12:28

By Caitlin
at 2017-10-11T20:20
at 2017-10-11T20:20

By Carolina Franco
at 2017-10-12T18:52
at 2017-10-12T18:52

By Ethan
at 2017-10-14T14:26
at 2017-10-14T14:26

By Eartha
at 2017-10-19T10:55
at 2017-10-19T10:55

By Elizabeth
at 2017-10-19T18:36
at 2017-10-19T18:36
Related Posts
Apple Watch錶面天氣顯示

By Olive
at 2017-01-24T04:04
at 2017-01-24T04:04
IOS 10.2.1 正式版推出

By Noah
at 2017-01-24T03:03
at 2017-01-24T03:03
iphone6/6s 皮革保護殼通用問題

By Elma
at 2017-01-24T00:55
at 2017-01-24T00:55
洛克人

By Dinah
at 2017-01-24T00:44
at 2017-01-24T00:44
iphone6換電池,卻拿不回舊電池!

By Genevieve
at 2017-01-24T00:34
at 2017-01-24T00:34